Skip to content

Set up SSO with Okta

Connect an Okta SAML 2.0 application to Infinite Audience. You need admin access to your Okta org and an owner/admin role in Infinite Audience with the Enterprise tier.

  1. In the Okta Admin Console, go to Applications → Applications and click Create App Integration.
  2. Choose SAML 2.0 and click Next.
  3. Give the app a name (e.g. “Infinite Audience”) and click Next.

On the Configure SAML step, enter the values from your Infinite Audience Connection Setup card:

  1. Single sign-on URL → paste our ACS URL. It looks like https://<app-domain>/__/auth/handler. Leave Use this for Recipient URL and Destination URL checked.
  2. Audience URI (SP Entity ID) → paste our SP Entity ID. It looks like https://<app-domain>/saml/<your-slug>.
  3. Name ID format → select EmailAddress.
  4. Application username → select Email.
  1. Click Next, choose “I’m an Okta customer adding an internal app”, and Finish.
  2. On the app’s Sign On tab, click View SAML setup instructions (or View Setup Instructions). This page lists the three values you need.
  3. Copy the Identity Provider Single Sign-On URL → this is our IdP SSO URL.
  4. Copy the Identity Provider Issuer → this is our IdP Entity ID.
  5. Copy the X.509 Certificate (the full -----BEGIN CERTIFICATE----- block) → this is the signing certificate.

On the Okta app’s Assignments tab, assign the people (or groups) who should be able to sign in. Only assigned users will be able to authenticate.

5. Complete the connection in Infinite Audience

Section titled “5. Complete the connection in Infinite Audience”
  1. Back in the Connection Setup card, paste the IdP Entity ID, IdP SSO URL, and the signing certificate PEM, then save.
  2. Claim and verify your email domain — see the DNS verification guide.
  3. Run Test Connection, confirm the NameID is your email, then Activate.

Users sign in at our sign-in page by entering their work email — not from an Okta dashboard tile. If a sign-in fails, see the troubleshooting guide.